This should only be used with Vault-installed Kafka. It will generate a new self-signed CA.
Add the package kafka-ca-rotation-pkg to your packages.txt file and set the desired rotation schedule in cron format at the following values.yaml file path: kafka.ca_rotation.schedule
Make sure it will not be running at the same time as certificate rotation.